<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing Multi Line Timestamp in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700641#M116014</link>
    <description>&lt;P&gt;Thanks for your second attempt. I tried, but still no luck.&lt;/P&gt;&lt;P&gt;Might there be the possibility, that the "Add Data" WebUI Wizard does not support this correctly?&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2024 09:54:36 GMT</pubDate>
    <dc:creator>jroedel</dc:creator>
    <dc:date>2024-10-01T09:54:36Z</dc:date>
    <item>
      <title>Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700629#M116007</link>
      <description>&lt;P&gt;I have to parse the timestamp of JSON logs and I would like to include subsecond precision. My JSON-Events start like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
  "instant" : {
    "epochSecond" : 1727189281,
    "nanoOfSecond" : 202684061
  },
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus I tried as config in props.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT=%s,\n    "nanoOfSecond" : %9N
TIME_PREFIX="epochSecond" :\s
MAX_TIMESTAMP_LOOKAHEAD=500&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That did unfortunately not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the right way to parse this time stamp with subsecond precision?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700629#M116007</guid>
      <dc:creator>jroedel</dc:creator>
      <dc:date>2024-10-01T09:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700635#M116011</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213890"&gt;@jroedel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you sure about the number of spaces?&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT=%s,\n\s*"nanoOfSecond"\s*:\s*%9N
TIME_PREFIX="epochSecond"\s*:\s*
MAX_TIMESTAMP_LOOKAHEAD=500&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700635#M116011</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-01T09:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700638#M116012</link>
      <description>&lt;P&gt;I tried, but still no luck&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-10-01 at 11.46.03.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32882iDF526E69B8CF1AC5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-10-01 at 11.46.03.png" alt="Screenshot 2024-10-01 at 11.46.03.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700638#M116012</guid>
      <dc:creator>jroedel</dc:creator>
      <dc:date>2024-10-01T09:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700639#M116013</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213890"&gt;@jroedel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TIME_FORMAT=%s,\n\s*\"nanoOfSecond\"\s*:\s*%9N
TIME_PREFIX=\"epochSecond\"\s*:\s*
MAX_TIMESTAMP_LOOKAHEAD=500&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700639#M116013</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-01T09:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700641#M116014</link>
      <description>&lt;P&gt;Thanks for your second attempt. I tried, but still no luck.&lt;/P&gt;&lt;P&gt;Might there be the possibility, that the "Add Data" WebUI Wizard does not support this correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700641#M116014</guid>
      <dc:creator>jroedel</dc:creator>
      <dc:date>2024-10-01T09:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700644#M116015</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213890"&gt;@jroedel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the Add Data feature doesn't permit to use this feature I suppose that it isn't possible event if it's strange.&lt;/P&gt;&lt;P&gt;I tried but I have the same result&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 10:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700644#M116015</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-01T10:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700663#M116017</link>
      <description>&lt;P&gt;Finally after a lot of testing I found a solution via &lt;STRONG&gt;transforms&lt;/STRONG&gt;.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[timestamp-fix]
INGEST_EVAL= _time=json_extract(_raw,"instant.epochSecond").".".json_extract(_raw,"instant.nanoOfSecond")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore, it turned out that regex is not allowed in TIME_FORMAT field in props.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 13:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700663#M116017</guid>
      <dc:creator>jroedel</dc:creator>
      <dc:date>2024-10-01T13:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Multi Line Timestamp</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700671#M116018</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213890"&gt;@jroedel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 14:07:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Multi-Line-Timestamp/m-p/700671#M116018</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-01T14:07:18Z</dc:date>
    </item>
  </channel>
</rss>

